Suspicious Domain Hunting (v1.0.16)

This pack provides all the necessary tools for the Suspicious Domain Hunting use case. It uses the CertStream integration to ingest new SSL certificates and alert for type-squatting domains with SSL certificate, these alerts are then analyzed and mitigated.

Author
Cortex XSOAR
Support
community
URL
https://live.paloaltonetworks.com/t5/cortex-xsoar-discussions/bd-p/Cortex_XSOAR_Discussions
Categories
Data Enrichment & Threat Intelligence

Layouts (1)

Playbooks (1)

Scripts (9)

README

Phishing domains impersonating an organization’s brand are a persistent threat that often slip through defenses. Analysts struggle to manually monitor certificate transparency logs and WHOIS registrations to catch phishing domains early.

The Suspicious Domain Hunting pack equips analysts with automation to proactively hunt for phishing domains targeting their organization. CertStream integration ingests newly issued SSL certificates in real-time, while WHOIS data and threat intel feeds are checked for domain registrations using the company brand. Analysts save hours of manual effort and can disrupt phishing campaigns before emails reach users.

This pack includes playbooks that:

Analysts also get out-of-the-box incident views and layouts tailored for Suspicious Domain Hunting, enabling efficient workflows to take action on high severity events.

What does this pack do?
Additional Information

Leverages the CertStream integration - configure your API key before installation.

Works best with Domain Reputation and Domain Enrichment integrations enabled.

For takedown automation, API access to domain registrar required.